Kubelet certificate authority is not configured

Provide a trusted CA so the API server can verify kubelet HTTPS serving certificates.

Description

--kubelet-certificate-authority specifies the CA file kube-apiserver uses to verify kubelet serving certificates. The API server does not verify those certificates by default, leaving connections over untrusted networks vulnerable to interception.

Potential impact

  • Logs or management requests can reach an endpoint impersonating a kubelet.
  • An incorrect CA or server name can cause verification failures and interrupt node management.

Remediation

  • Set --kubelet-certificate-authority to the trusted CA bundle that issued the kubelet serving certificates.
  • Check that the connection address matches the certificate’s DNS name or IP address and that the API server can read the file.
  • Configure kubelet authentication and authorization, then test successful trusted connections and rejection of untrusted certificates.

Examples

These historical arguments use Kubernetes 1.6.0. Substitute the actual CA file and mount path used by your supported deployment.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver"]

No CA is specified for verifying the kubelet serving certificate. HTTPS encryption alone does not verify the server’s identity.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: gcr.io/google_containers/kube-apiserver-amd64:v1.6.0
      command: ["kube-apiserver"]
      args: ["--kubelet-certificate-authority=/path/to/any/cert/file.pem"]

A verification CA file is specified. Its contents must actually correspond to the kubelet serving certificate.

References